Note on CVE-2025-45767 #813
Locked
panva
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
The following concerns
CVE-2025-45767/BDSA-2025-8040/ GHSA-m523-xm42-q7ff / https://nvd.nist.gov/vuln/detail/CVE-2025-45767 / https://www.cve.org/CVERecord?id=CVE-2025-45767I've responded to this report back in April and have not heard back from the reporter since.
The report's description is inaccurate and false since the jose module does enforce RSA key sizes and always has for all currently supported major versions.
As far as HMAC key sizes go I responded with the following and would say that symmetric secret key length enforcement is generally put forth on the user, not the module. This exact same report has been received by a number of other libraries in the JOSE ecosystem and my $.02 is they should all be rejected.
My response from back in April follows:
For the reasons above I am of a strong belief that this shouldn't have been assigned in the first place and have requested this CVE be rejected.
Beta Was this translation helpful? Give feedback.
All reactions